Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,320 rules
PowerShell PSAsyncShell Reverse Shell Activity via Script Block Logging
Detects PowerShell use of PSAsyncShell by matching the tool name in logged script block text.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh121Free2022-10-04Windows Registry: Modify User Shell Folders Startup Values for Persistence
Alerts on Windows Registry changes to User Shell Folders startup-related values that may be used to establish persistence.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh393Free2022-10-01Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Flags w3wp.exe-launched commands matching China Chopper webshell execution patterns in Windows process creation logs.
Florian Roth (Nextron Systems), MSTI (query), Huntrule TeamWindowsprocess_creationHigh291Free2022-10-01Atlassian Bitbucket Command Injection Attempt via Archive API Parameters (Webserver)
Alerts on Bitbucket REST archive query parameters containing a %00--exec execution marker.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh92Free2022-09-29Windows IIS connection string decryption via aspnet_regiis -pdf
Flags aspnet_regiis.exe runs that target IIS connectionStrings for decryption using -pdf.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh144Free2022-09-28PowerShell ScriptBlock Matching Invoke-Mimikatz Credential Dump Commands (Windows)
Detects PowerShell ScriptBlocks containing Mimikatz-like credential dump and certificate extraction command strings.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsps_scriptHigh112Free2022-09-28AnyDesk Windows: suspicious executable/DLL writes excluding gcapi.dll
Alerts when AnyDesk.exe or AnyDeskMSI.exe writes .dll/.exe files, excluding gcapi.dll.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh173Free2022-09-28Windows ImagingDevices.exe Spawns Unusual Parent/Child Processes
Alerts when ImagingDevices.exe participates in atypical process parent/child chains on Windows, based on process creation telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh273Free2022-09-27Windows: Unusual Child Process Spawn by dns.exe
Alerts when dns.exe launches an unexpected child process other than conhost.exe.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-27Windows dns.exe Deletes Files with Unexpected Targets
Alerts when dns.exe deletes any file other than dns.log on Windows.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowsfile_deleteHigh82Free2022-09-27Windows: Unusual File Modification by dns.exe
Alert on dns.exe changing files other than dns.log, which can indicate suspicious or compromised system activity.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowsfile_changeHigh423Free2022-09-27Windows Remote Thread Creation via rundll32 Triggered by wab*, wabmig, or ImagingDevices
Alerts on remote thread creation targeting rundll32.exe from wab* or ImagingDevices.exe process images on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_remote_threadHigh236Free2022-09-27Windows: w32tm.exe Timer/Delay Usage via stripchart Parameters
Flags w32tm.exe executions using stripchart delay-related parameters that can support timed automation on Windows.
frack113, Huntrule TeamWindowsprocess_creationHigh472Free2022-09-25Windows Process Creation: Renamed createdump.exe Used for .dmp Memory Dumps
Flags renamed createdump.exe executions on Windows that use full dump flags and produce .dmp files.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-09-20Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh81Free2022-09-20